Page MenuHomeVyOS Platform

Multiple VyOS privilege-boundary flaws allow low-privilege users to execute root commands and disclose sensitive configuration
Open, HighPublicBUG

Description

This report package contains a merged root-cause analysis of multiple VyOS privilege-boundary vulnerabilities found during an authorized audit.

The uploaded archive is organized under security-reports/merged/. Each root-cause folder contains a SUMMARY.md and DETAIL.md. The DETAIL.md files list the
affected commands, GraphQL operations, local binaries, sockets, or generated files, and include one complete end-to-end PoC example with setup, trigger,
verification, and cleanup steps.

The main impact classes are:

1. Low-privilege GraphQL token users can reach op-mode handlers without equivalent CLI/operator authorization checks. Several handlers then pass attacker-
controlled values into root shell command strings, resulting in root command execution.

2. The shared interface_exists() helper validates interface names by checking os.path.exists('/sys/class/net/{interface}'). Path traversal can satisfy this guard
with attacker-created /tmp files, after which the original interface string reaches root shell command sinks.

3. Management API keys or key-bearing runtime/config state are exposed to lower-privileged users through local files, generated config caches, cli-shell-api
output, or GraphQL-accessible paths. Recovered keys can provide full management API access and root command execution through supported configuration workflows.

4. Several generated secret files and runtime artifacts are world-readable, exposing VPN, TACACS, stunnel, Zabbix, API, and archived configuration secrets to
local low-privilege users.

5. World-writable IPC or include paths allow local low-privilege users to influence privileged services such as configd, hostsd/PowerDNS, and zabbix-agent.

6. Over-broad Linux file capabilities and sudoers rules expose privileged network, system, packet capture, and root command execution capabilities to local low-
privilege or operator users.

7. nginx error-log handling preserves attacker-controlled CRLF or terminal control characters, enabling unauthenticated log trust-boundary injection.

The reports distinguish authenticated, local, operator, and unauthenticated attack models. They also distinguish direct root command execution, service-account
command execution, sensitive-read disclosure, and non-RCE privilege-boundary impacts. Individual DETAIL.md files should be treated as the authoritative
reproduction and remediation notes for each root cause.{F116477488}

Details

Version
vyos-1x-master
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

I uploaded the report archive, but I do not see it attached/available in the submission view. To make sure the materials are accessible, I also placed the

complete report package here:

https://drive.google.com/file/d/1Ije24_JPDOUIxnK5-exV0iaDlM47mtSA/view?usp=sharing

The archive contains the merged root-cause reports under security-reports/merged/, including SUMMARY.md and DETAIL.md files for each vulnerability class, with
affected commands/paths and complete PoC steps.

i report them on github security advisor